Data Processing Agreement
Last updated: August 30, 2026
This agreement applies whenever GTM Studio processes personal data on behalf of a client. It is part of the engagement contract and follows Article 28 GDPR. Plain language on purpose; the obligations are real.
1. Parties, scope, and roles
The client is the data controller. GTM Studio ([legal entity name], [address]) is the data processor. This DPA covers all personal data we touch while building and running the client's go-to-market system.
2. Details of the processing
Subject matter: market mapping, signal tracking, account scoring, and outreach operations. Duration: the engagement term. Data subjects: people in business roles at companies in the client's market. Data categories: name, role, company, work contact details, and public business signals. No special categories of data are processed.
3. Instructions
We process personal data only on the client's documented instructions — the engagement scope and written changes to it. If an instruction would break the law, we say so instead of following it.
4. Confidentiality
Everyone who works on an engagement is bound to confidentiality by contract. Access to client data is limited to the people who run that engagement.
5. Security measures
Encryption in transit, access on a need-to-use basis, two-factor authentication on all work accounts, and separation of each client's data in the client's own tool accounts. A detailed measure list is kept in the engagement annex.
6. Subprocessors
The client authorizes the subprocessors listed in the engagement annex (hosting, enrichment, outreach, and CRM tools agreed for the engagement). We announce changes in advance and the client can object on reasonable data protection grounds.
7. Data subject requests
Requests from data subjects go to the client. We help with the technical side — finding, correcting, exporting, or deleting the data — without undue delay.
8. Breach notification
If we learn of a personal data breach affecting client data, we notify the client without undue delay and share what we know so the client can meet its own deadlines.
9. Deletion and return
The system and its data belong to the client and live in the client's accounts. At the end of the engagement we hand over anything still in our hands and delete our copies, unless law requires retention.
10. Audits
We answer reasonable audit questions and provide the documentation needed to show compliance. On-site audits happen at most once a year, with notice, during business hours.
11. International transfers
Transfers outside the EEA rely on EU Standard Contractual Clauses or an adequacy decision, as listed per subprocessor in the annex.
12. Liability, precedence, and term
Liability follows the engagement contract. If this DPA conflicts with the contract, the DPA wins on data protection matters. The DPA runs as long as we process personal data for the client.